Back to skill

Security audit

Discord中心

Security checks across malware telemetry and agentic risk

Overview

This Discord skill is not clearly malicious, but it asks for broad local command and file authority while its Discord automation scope is vague and under-scoped.

Review before installing. Use it only in an environment where Discord bot actions, local file access, and command execution are acceptable, and require explicit confirmation for sending messages, bulk operations, archive retrieval, file writes, or shell commands. Avoid giving it broad workspace or sensitive credential access until the publisher narrows the documented scope.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is advertised as a Discord Bot workflow helper, but the documentation expands into generic file processing and system command execution. This scope mismatch is dangerous because it can cause an agent or user to invoke powerful local capabilities under the trusted banner of a narrow communication integration, increasing the chance of unintended file access or command execution.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Claiming shell or command-execution capability is high risk when the skill's stated purpose is Discord Bot API automation. In an agent environment with exec access, this can be used to run arbitrary local commands unrelated to Discord, enabling host manipulation, data exfiltration, or persistence if the skill is over-trusted.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill advertises broad file read/write handling beyond what is necessary for a Discord messaging workflow. In context, this broadens the blast radius from API interactions to local data access, creating opportunities for accidental overwrites, sensitive file exposure, or using the skill as a generic file-manipulation wrapper.

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
The documentation advertises expanded paid features such as batch multi-channel sending and communication archive/retrieval that exceed the narrower manifest description. This discrepancy can mislead users and agents about the skill's true authority and data-handling behavior, especially where archival or mass messaging affects privacy, compliance, or abuse potential.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation guidance is overly broad and overlaps with generic productivity or automation requests, which increases the chance that the skill is invoked outside its intended Discord scope. Because the skill exposes read, write, and exec tools, overbroad triggering materially raises the risk of misuse through prompt routing rather than through explicit user intent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The core capability statement is too vague to define a safe operational boundary. In a skill-based agent system, vague scope descriptions can cause the model to grant the skill broad latitude, which is especially risky when the skill also claims file and command capabilities.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill description does not clearly warn users that it may send messages, execute commands, write files, or perform external/API actions with side effects. This is dangerous because users may authorize the skill expecting passive analysis, while it actually enables state-changing operations across local and external systems.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.